SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12666

HIGH · CVSS 8.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM MQ versions 9.1 through 10.0 are vulnerable to XML external entity injection in the processing of MQRFH2 headers, which could allow authenticated attackers to access sensitive information or trigger a denial of service. Organizations using these versions of IBM MQ should prioritize patching to mitigate the risk of data exposure and service disruption. This vulnerability is particularly critical for environments handling sensitive data or requiring high availability.

CVE
CVE-2026-12666
Severity
HIGH
CVSS
8.1
EPSS
0.26%
Java

Original NVD Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.